← Back
(Updated) Microsoft Defender for Office 365: Two new data tables in Advanced hunting (preview)
MC1088729 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-10-06 14:17:50
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Microsoft Defender XDR
Tags
Updated message, New feature, User impact, Admin impact
Master tags
Security
Roadmap IDs

One-line summary

Defender for Office 365 adds CampaignInfo and FileMaliciousContentInfo tables to Advanced Hunting, aiding threat investigations across email, SharePoint, OneDrive, and Teams.

Similar updates

More like this
MC1042926 (Updated) Microsoft Defender for Office 365: Platform migration for enhanced data storage and performance
(Updated) Microsoft Defender for Office 365: Platform migration for enhanced data storage and performance Defender for Office 365 is migrating its data platform to improve performance, data consistency, and reliability; Phase 2 rollout completes by end of December 2025. As part of our ongoing efforts to enhance performance and scalability,.
MC1150118 Microsoft Defender for Office 365: New records in Streaming API and Sentinel EmailEvents table
Microsoft Defender for Office 365: New records in Streaming API and Sentinel EmailEvents table Microsoft Defender for Office 365 and Sentinel will now store both current and historical email verdict/location changes in the EmailEvents table, improving threat analysis accuracy. [Introduction] To improve visibility and alignment across Microsoft.
MC1163754 Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365
Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365 Defender for Office 365's Deep Analysis tab gains enhanced UI, improved detonation chains, expanded metadata, and exportable insights for better threat investigation, rolling out Nov 2025. We’re excited to share recent enhancements to the Deep.
MC992217 (Updated) Microsoft Defender: Changes to Defender for Cloud Apps alerts
(Updated) Microsoft Defender: Changes to Defender for Cloud Apps alerts Defender for Cloud Apps alerts in Defender XDR will update alert source fields and alert ID prefixes for new alerts, affecting APIs, SIEM, and custom automations; rollout completes by late June 2025. Coming soon for Microsoft Defender for Cloud Apps: A change to alerts.
MC1042925 (Updated) Microsoft Defender for Office 365: Enhancing page load performance
(Updated) Microsoft Defender for Office 365: Enhancing page load performance Defender for Office 365 will improve portal page load times, starting with Submission page in March 2025; no downtime or required admin action during phased rollout. Updated July 9, 2025: We have updated the timeline below. At Microsoft Defender for Office 365, we are.
MC1200058 Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal
Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal Admins can now block external users in Microsoft Teams via the Tenant Allow/Block List in the Microsoft Defender portal, controlling a... [Introduction] We’re introducing an integration between Microsoft Teams and Microsoft Defender for.

Details

Summary
Microsoft Defender for Office 365 will add two new Advanced hunting data tables, CampaignInfo and FileMaliciousContentInfo, rolling out from June to November 2025. These tables help security teams investigate email campaigns and malicious files across email, SharePoint, OneDrive, and Teams, with no admin action needed.

Body (from Message Center)

Updated October 6, 2025: We have updated the content. Thank you for your patience. 

Coming soon for Microsoft Defender for Office 365: We are excited to announce the new CampaignInfo and FileMaliciousContentInfo data tables in Advanced hunting under Email & collaboration schema.

[When this will happen:]

Public Preview: We will begin rolling out early June 2025 and expect to complete by late June 2025.

General Availability (Worldwide, GCC, GCC High, DoD): General Availability: We will begin rolling out early July 2025 and expect to complete by late November 2025, covering both Advanced Hunting and Sentinel availability.

[How this will affect your organization:]

The new tables will be available by default. SOC teams will be able to see two new data tables in Defender > Advanced hunting > Email & collaboration schema.

1. CampaignInfo

The CampaignInfo table in the Advanced hunting schema contains information about email campaigns identified by Defender for Office 365. The table will have this schema to help the security teams to investigate threats targeting their users and organization:

admin controls

2. FileMaliciousContentInfo

The FileMaliciousContentInfo table in the Advanced hunting schema contains information about files that were processed by Defender for Office 365 in Microsoft SharePoint Online, Microsoft OneDrive, and Microsoft Teams. The table will have this schema to help the security teams to investigate threats targeting their users and organization:

admin controls

Here are a few sample queries to get you started:

//Emails sent as part of phishing campaigns

CampaignInfo

| where Timestamp > ago(7d)

| where CampaignType has "Phish"

| project NetworkMessageId, RecipientEmailAddress, CampaignName, CampaignId, CampaignType

| join (EmailEvents | where Timestamp > ago(7d)) on NetworkMessageId, RecipientEmailAddress

| project Timestamp, NetworkMessageId, Subject, SenderMailFromAddress, RecipientEmailAddress, LatestDeliveryLocation, LatestDeliveryAction, CampaignId, CampaignName, CampaignType

//Files identified as Malware modified in last 1 day

FileMaliciousContentInfo

| where ThreatTypes == "Malware"

| where LastModifiedTime > ago(1d)

[What you need to do to prepare:]

This rollout will happen automatically by the specified dates with no admin action required before the rollout. Review your current configuration to assess the impact on your organization. You may want to notify your users about this change and update your relevant documentation.

After the Public Preview rollout, we will update this post with new documentation.

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Review configuration",
      "Notify users",
      "Update documentation"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Defender for Office 365 adds CampaignInfo and FileMaliciousContentInfo tables to Advanced Hunting, aiding threat investigations across email, SharePoint, OneDrive, and Teams.",
    "ai_topics": [
      "Defender",
      "SharePoint",
      "OneDrive",
      "Teams"
    ],
    "category": "stayInformed",
    "details_map": {
      "Summary": "Microsoft Defender for Office 365 will add two new Advanced hunting data tables, CampaignInfo and FileMaliciousContentInfo, rolling out from June to November 2025. These tables help security teams investigate email campaigns and malicious files across email, SharePoint, OneDrive, and Teams, with no admin action needed."
    },
    "id": "MC1088729",
    "importance": 1,
    "is_major_change": false,
    "last_modified": "2025-10-06T14:17:50Z",
    "ms_products": [
      "Defender"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Microsoft Defender XDR"
    ],
    "severity": "normal",
    "tags": [
      "Updated message",
      "New feature",
      "User impact",
      "Admin impact"
    ],
    "title": "(Updated) Microsoft Defender for Office 365: Two new data tables in Advanced hunting (preview)"
  }
}